In the last several decades, the automotive industry has come to incorporate\nthe latest Information and Communications (ICT) technology, increasingly\nreplacing mechanical components of vehicles with electronic components. These\nelectronic control units (ECUs) communicate with each other in an in-vehicle\nnetwork that makes the vehicle both safer and easier to drive. Controller Area\nNetworks (CANs) are the current standard for such high quality in-vehicle\ncommunication. Unfortunately, however, CANs do not currently offer protection\nagainst security attacks. In particular, they do not allow for message\nauthentication and hence are open to attacks that replay ECU messages for\nmalicious purposes. Applying the classic cryptographic method of message\nauthentication code (MAC) is not feasible since the CAN data frame is not long\nenough to include a sufficiently long MAC to provide effective authentication.\nIn this paper, we propose a novel identification method, which works in the\nphysical layer of an in-vehicle CAN network. Our method identifies ECUs using\ninimitable characteristics of signals enabling detection of a compromised or\nalien ECU being used in a replay attack. Unlike previous attempts to address\nsecurity issues in the in-vehicle CAN network, our method works by simply\nadding a monitoring unit to the existing network, making it deployable in\ncurrent systems and compliant with required CAN standards. Our experimental\nresults show that the bit string and classification algorithm that we utilized\nyielded more accurate identification of compromised ECUs than any other method\nproposed to date. The false positive rate is more than 2 times lower than the\nmethod proposed by P.-S. Murvay et al. This paper is also the first to identify\npotential attack models that systems should be able to detect.\n